audit-labs/audit-tools

A collection of scripts, queries, and other goodies you can use in an audit. audit automation compliance evidence scripts

Commit 2364326274

23643262742ac4612fb9a2188d11184f0f077d8f

parent: 043b3b7971

Unsigned

Christian Cleberg <156287552+ccleberg@users.noreply.github.com> · 2024-10-25 16:56 UTC
committer: <noreply@github.com>

add SQL database password test

Layout: unified · split

db_passwords/sql/get_data.sql added +30
@@ -0,0 +1,30 @@
1/*
2References:
31. https://learn.microsoft.com/en-us/sql/relational-databases/security/password-policy
42. https://learn.microsoft.com/en-us/sql/t-sql/functions/loginproperty-transact-sql
5*/
6
7SELECT
8 name,
9 principal_id,
10 sid,
11 type,
12 type_desc,
13 is_disabled,
14 create_date,
15 modify_date,
16 default_database_name,
17 default_language_name,
18 credential_id,
19 is_policy_checked,
20 is_expiration_checked,
21 password_hash,
22 LOGINPROPERTY(name, 'IsMustChange') AS IsMustChange,
23 LOGINPROPERTY(name, 'IsLocked') AS IsLocked,
24 LOGINPROPERTY(name, 'LockoutTime') AS LockoutTime,
25 LOGINPROPERTY(name, 'PasswordLastSetTime') AS PasswordLastSetTime,
26 LOGINPROPERTY(name, 'IsExpired') AS IsExpired,
27 LOGINPROPERTY(name, 'BadPasswordCount') AS BadPasswordCount,
28 LOGINPROPERTY(name, 'BadPasswordTime') AS BadPasswordTime,
29 LOGINPROPERTY(name, 'HistoryLength') AS HistoryLength
30FROM sys.sql_logins;
db_passwords/sql/test.py added +76
@@ -0,0 +1,76 @@
1"""
2Checks SQL Server user data for compliance with Windows policies.
3"""
4
5# Import packages
6import pandas as pd
7from io import StringIO
8
9# Sample data as a CSV string
10data = """name,principal_id,sid,type,type_desc,is_disabled,create_date,modify_date,default_database_name,default_language_name,credential_id,is_policy_checked,is_expiration_checked,password_hash,IsMustChange,IsLocked,LockoutTime,PasswordLastSetTime,IsExpired,BadPasswordCount,BadPasswordTime,HistoryLength
11user1,1,,S,SQL_LOGIN,0,2023-01-15 10:35:00,2023-01-15 10:35:00,master,us_english,NULL,1,0,0x01004086CEB6772AE2356381B9B069D4E02C0185D5A06CFA3822,0,0,,2023-01-15 10:35:00,0,0,,5
12user2,267,,S,SQL_LOGIN,0,2023-02-20 20:49:00,2023-02-20 20:49:00,master,us_english,NULL,0,0,0x01003E3A7A6F88A8F548540ECB2043946AC2545120424CCD8782,1,0,,2023-02-20 20:49:00,0,1,2023-02-20 20:50:00,3
13user3,268,,S,SQL_LOGIN,0,2023-03-10 11:20:00,2023-03-10 11:20:00,Adminserver,us_english,NULL,1,0,0x010042516769FBC191A67840731CB36B41EFDACC97BE8264281F,0,0,,2023-03-10 11:20:00,0,0,,4
14user4,269,,S,SQL_LOGIN,0,2023-04-01 10:40:00,2023-04-01 11:32:00,Adminserver,us_english,NULL,1,0,0x01005F3B351B26E2DB7C7FD3C7ED02B3FD2EDC09BB2BF13DA3E5,0,1,2023-04-01 11:32:00,2023-04-01 10:40:00,0,3,2023-04-01 11:30:00,2
15user5,270,,S,SQL_LOGIN,0,2023-05-05 12:33:00,2023-05-05 12:33:00,master,us_english,NULL,1,0,0x0100AE15D55972BB3D6C6283921711CD4A208747888BEEFED71B,0,0,,2023-05-05 12:33:00,0,0,,6
16user6,272,,S,SQL_LOGIN,0,2023-06-15 11:46:00,2023-06-15 11:46:00,Adminserver,us_english,NULL,1,1,0x0100F12FAE790FCE0FF356A0948211AE4052653503E1BBC28FAB,0,0,,2023-06-15 11:46:00,0,0,,7
17user7,279,,S,SQL_LOGIN,0,2023-07-20 12:50:00,2023-07-20 12:50:00,Adminserver,us_english,NULL,1,1,0x01004856A222264E62219236AB6AC7E5B622F1E53D1CCA2AF9B8,0,0,,2023-07-20 12:50:00,0,0,,8
18user8,284,,S,SQL_LOGIN,0,2023-08-25 13:56:00,2023-08-25 13:56:00,master,us_english,NULL,1,1,0x0100723BEDBE69779CD3087C0E60AD69C33CC7E969F78DA2498A,0,0,,2023-08-25 13:56:00,0,0,,9
19"""
20
21# Load the data into a pandas DataFrame
22df = pd.read_csv(StringIO(data))
23
24# Function to apply rules and generate report
25def apply_rules_and_report(df):
26 report = []
27 for index, row in df.iterrows():
28 result = {
29 'Name': row['name'],
30 'Type Check': '',
31 'Policy Check': '',
32 'Expiration Check': '',
33 'Reason': ''
34 }
35
36 # Check the type_desc
37 if row['type_desc'] == 'SQL_LOGIN':
38 result['Type Check'] = 'SQL_LOGIN'
39 elif row['type_desc'] == 'WINDOWS_LOGIN':
40 result['Type Check'] = 'N/A'
41 result['Reason'] = 'Refer to Windows password policy.'
42 else:
43 result['Type Check'] = 'Manual Review'
44 result['Reason'] = 'Reviewer to manually review.'
45
46 # Check if password policy is enforced
47 if row['is_policy_checked'] == 1:
48 result['Policy Check'] = 'PASS'
49 result['Reason'] += ' Password policy is enforced. Reviewer to check the assigned policy.'
50 else:
51 result['Policy Check'] = 'FAIL'
52 result['Reason'] += ' Password policy is not enforced.'
53
54 # Check if password expiration is enforced
55 if row['is_expiration_checked'] == 1:
56 result['Expiration Check'] = 'PASS'
57 result['Reason'] += ' Password expiration is enforced. Reviewer to check the expiration policy.'
58 else:
59 result['Expiration Check'] = 'FAIL'
60 result['Reason'] += ' Password expiration is not enforced.'
61
62 report.append(result)
63
64 return report
65
66# Main function to run the script
67def main():
68 # Apply rules and generate report
69 report = apply_rules_and_report(df)
70 report_df = pd.DataFrame(report)
71
72 # Print the report
73 print(report_df)
74
75if __name__ == "__main__":
76 main()